Cybersecurity

WordPress Exploited: Hackers Target Millions of Sites After Patch

Cybercriminals are actively exploiting recently patched security flaws in WordPress, threatening millions of websites globally. Updates were rushed out last week, but many sites remain vulnerable.

Joshua Ramos
Joshua Ramos covers cybersecurity for Techawave.
2 min read0 views
WordPress Exploited: Hackers Target Millions of Sites After Patch
Share

Hackers are actively exploiting critical security vulnerabilities in the widely used WordPress content management system, compromising websites that have not yet applied recent patches. Cybersecurity firms Patchstack, Hexastrike, and WatchTowr issued urgent warnings, indicating that malicious actors are already leveraging the flaws in live attacks. WordPress released updates last week to address two severe bugs, even enabling forced updates for some users to mitigate the immediate risk.

The affected versions of WordPress include 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. While WordPress reports over 400 million websites utilize these versions, many may have already been updated. However, cybersecurity consultant Daniel Card analyzed approximately 4,200 WordPress sites and estimated that fewer than 15% remain vulnerable. Extrapolating this figure suggests that potentially tens of millions of websites could still be at risk globally.

Ongoing Threat to Web Infrastructure

The exploitation of these vulnerabilities highlights the persistent threat landscape facing web administrators. Even with prompt patching by software vendors like WordPress, the sheer scale of internet infrastructure means that a significant number of sites can remain susceptible for extended periods. The speed at which attackers move to exploit newly disclosed vulnerabilities, often referred to as "in the wild" exploitation, underscores the critical importance of immediate security updates.

Researchers have credited proactive measures such as automatic updates pushed by Automattic (the company behind WordPress.com), defensive actions by Cloudflare in blocking attacks, and the use of web application firewalls (WAFs) for limiting the overall impact. These tools and practices are vital for protecting against widespread breaches. However, websites that lack these safeguards or have not applied the latest security fixes remain prime targets for these ongoing attacks.

The attack vector, while not fully detailed, is believed to stem from the recently patched flaws which could allow unauthorized access and manipulation of website content or data. Organizations and individuals relying on WordPress for their online presence are strongly advised to verify their software is updated to the latest secure version. Failing to do so leaves them exposed to potential data breaches, defacement, or other malicious activities. This situation serves as a stark reminder for all website owners to maintain vigilance and prioritize regular security maintenance to safeguard their digital assets against ever-evolving cyber threats.

Share